<head><meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1">
<title>kali工具箱</title>
<script src="./static/bootstrap.min.js"></script>
<link rel="stylesheet" href="./static/main.css">
<link rel="stylesheet" href="./static/bootstrap.min.css">
<style type="text/css" id="syntaxhighlighteranchor"></style>
</head>
<main class="main-container ng-scope" ng-view="">
<div class="main receptacle post-view ng-scope">
<article class="entry ng-scope" ng-controller="EntryCtrl" ui-lightbox="">
<section class="entry-content ng-binding" ng-bind-html="postContentTrustedHtml">
<section class="l-section"><div class="l-section-h i-cf"><h2>javasnoop Package Description</h2>
<p style="text-align: justify;">Normally, without access to the original source code, testing the security of a Java client is unpredictable at best and unrealistic at worst. With access the original source, you can run a simple Java program and attach a debugger to it remotely, stepping through code and changing variables where needed. Doing the same with an applet is a little bit more difficult.</p>
<p>Unfortunately, real-life scenarios don’t offer you this option, anyway. Compilation and decompilation of Java are not really as deterministic as you might imagine. Therefore, you can’t just decompile a Java application, run it locally and attach a debugger to it.</p>
<p>Next, you may try to just alter the communication channel between the client and the server, which is where most of the interesting things happen anyway. This works if the client uses HTTP with a configurable proxy. Otherwise, you’re stuck with generic network traffic altering mechanisms. These are not so great for almost all cases, because the data is usually not plaintext. It’s usually a custom protocol, serialized objects, encrypted, or some combination of those.</p>
<p>JavaSnoop attempts to solve this problem by allowing you attach to an existing process (like a debugger) and instantly begin tampering with method calls, run custom code, or just watch what’s happening on the system.
</p><p>Source: https://code.google.com/p/javasnoop/</p>
<p><a href="http://code.google.com/p/javasnoop/" variation="deepblue" target="blank">javasnoop Homepage</a> | <a href="http://git.kali.org/gitweb/?p=packages/javasnoop.git;a=summary" variation="deepblue" target="blank">Kali javasnoop Repo</a></p>
<ul>
<li>Author: www.aspectsecurity.com</li>
<li>License: GPLv3</li>
</ul>
<h3>Tools included in the javasnoop package</h3>
<h5>javasnoop – Intercept Java applications locally</h5>
<p>JavaSnoop attempts to attach to an existing process (like a debugger) and instantly begin tampering with method calls, run custom code, or just watch what’s happening on the system.</p>
<h3>javasnoop Usage Example</h3>
<code><a class="__cf_email__" href="/cdn-cgi/l/email-protection" data-cfemail="97e5f8f8e3d7fcf6fbfe">[email&#160;protected]</a><script data-cfhash='f9e31' type="text/javascript">/* <![CDATA[ */!function(t,e,r,n,c,a,p){try{t=document.currentScript||function(){for(t=document.getElementsByTagName('script'),e=t.length;e--;)if(t[e].getAttribute('data-cfhash'))return t[e]}();if(t&&(c=t.previousSibling)){p=t.parentNode;if(a=c.getAttribute('data-cfemail')){for(e='',r='0x'+a.substr(0,2)|0,n=2;a.length-n;n+=2)e+='%'+('0'+('0x'+a.substr(n,2)^r).toString(16)).slice(-2);p.replaceChild(document.createTextNode(decodeURIComponent(e)),c)}p.removeChild(t)}}catch(u){}}()/* ]]> */</script>:~# javasnoop</code>
<p><a href='full/336b118501688c3498e7e8da01fc985726224daa.jpg'><img src='full/336b118501688c3498e7e8da01fc985726224daa.jpg' alt="javasnoop" width="920" class="aligncenter size-full wp-image-3890" srcset="http://tools.kali.org/wp-content/uploads/2014/02/javasnoop-300x228.png 300w, http://tools.kali.org/wp-content/uploads/2014/02/javasnoop-1024x778.png 1024w, http://tools.kali.org/wp-content/uploads/2014/02/javasnoop.png 1828w" sizes="(max-width: 1828px) 100vw, 1828px"></a></p>
</div></section><div style="display:none">
<script src="//s11.cnzz.com/z_stat.php?id=1260038378&web_id=1260038378" language="JavaScript"></script>
</div>
</main></body></html>
